Junglewise Threat Intelligence

asymmetric-effort specifyjs SSRF via unvalidated redirects in secureFetch

Severity: medium · CVSS 6.9 · Published 2026-07-02

Technologies: Asymmetric Effort Specifyjs, @asymmetric-effort/specifyjs (npm). Vendors: Asymmetric Effort, npm.

Executive brief

A vulnerability in the specifyjs library could allow an attacker to bypass security checks and access internal network resources. The software's secure data fetching component failed to validate the destination of web redirects, potentially allowing a request intended for a secure public site to be redirected to a private internal server. This could lead to unauthorized access to internal services or data manipulation within a corporate network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in `@asymmetric-effort/specifyjs` within the `secureFetch` component located in `core/src/shared/secure-fetch.ts`. While the `assertSecureUrl` function validates the initial request URL, it does not validate subsequent URLs when the `fetch()` API follows HTTP redirects (up to the default 20 hops). An attacker can provide a valid HTTPS URL that redirects to an unvalidated internal destination, such as `http://internal-service/`. This issue is fixed in version 0.2.136 by defaulting `secureFetch` to `redirect: 'error'`, which rejects all redirects unless explicitly overridden by the caller.

Affected products

  • asymmetric-effort specifyjs < 0.2.136

Timeline

  • 2026-05-29: disclosed: Vulnerability identified during penetration test code review.
  • 2026-05-29: patched: Fixed in version 0.2.136 via commit 25d1fb4.
  • 2026-07-02: advisory: GitHub Advisory GHSA-j5qp-p44g-2m49 published.

References

Related threats